Re: [Full-disclosure] File Access Vulnerability in Easy File Sharing Web Server

2009-12-15 Thread Thor (Hammer of God)
I actually DID try to access the .sdb in Ubuntu but that was before I identified the file format of the db as myDB as noted. I do not know of a 'nix based tool for access to the db. If you just want to verify, you can open the .sdb with a text/hex editor and parse out a filename for yourself -

Re: [Full-disclosure] File Access Vulnerability in Easy File Sharing Web Server

2009-12-15 Thread Rohit Patnaik
Wow. Very nice find. One question: all the cited tools are Windows executables. Has there been any attempt to run the database viewer in Linux via Wine? I'm wondering if I'm going to have to set up a VM to try to confirm this, or if I can try to do this via Wine. Although the n3td3v drama is e

[Full-disclosure] File Access Vulnerability in Easy File Sharing Web Server

2009-12-15 Thread Thor (Hammer of God)
File Access Vulnerability in Easy File Sharing Web Server Discovered by: Timothy "Thor" Mullen Testing by Steve "Raging Haggis" Moffat, Hammer of God, Bermuda Labs Product:Easy File Sharing Web Server, current versions, default installation Vendor: http://www.sharing-file.com/

Re: [Full-disclosure] Google Chrome 3.0.195.33 leaks DNS data queries outsitde of proxy if dns pre-fetching is enabled

2009-12-15 Thread nixlists
On Tue, Dec 15, 2009 at 9:39 PM, Dan Kaminsky wrote: > Nix, > >    Proxies are not a security technology in the way you think they are. They're not, but many still use the browsers' proxy features hoping for more anonymity and avoidance of data sniffing. Most users are not security experts. They

Re: [Full-disclosure] Google Chrome 3.0.195.33 leaks DNS data queries outsitde of proxy if dns pre-fetching is enabled

2009-12-15 Thread Dan Kaminsky
Nix, Proxies are not a security technology in the way you think they are. Way back in the day, NAT didn't exist. In order for large numbers of users to share small number of IP addresses, application layer gateways -- proxies -- needed to be written such that a backend client could "ask" f

Re: [Full-disclosure] Google Chrome 3.0.195.33 leaks DNS data queries outsitde of proxy if dns pre-fetching is enabled

2009-12-15 Thread nixlists
The point is besides the fact that you can configure Chrome to proxy through Tor or anything else, Chrome is not supposed to leak DNS - it's a bug that Firefox currently does not have for instance. Many users use proxies to avoid corporate and other firewalls, and to prevent leakage of information

[Full-disclosure] VMSA-2009-0017 VMware vCenter, ESX patch and vCenter Lab Manager releases address cross-site scripting issues

2009-12-15 Thread VMware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - --- VMware Security Advisory Advisory ID: VMSA-2009-0017 Synopsis: VMware vCenter, ESX patch and vCenter Lab Manager releases ad

[Full-disclosure] [ MDVSA-2009:333 ] postgresql

2009-12-15 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:333 http://www.mandriva.com/security/

[Full-disclosure] CarolinaCon-VI/2010 - Call for Papers/Speakers

2009-12-15 Thread Vic Vandal
InfoSec professionals, h4x0rs, script kidz, posers, and government spies: "CarolinaCon" is back yet again! Yes, for about the price of your average movie admission with popcorn and a drink, YOU are invited to join us for yet another intimate and informative weekend of technology education. What

Re: [Full-disclosure] Global warming - it's all about the money

2009-12-15 Thread Jared DeMott
Paul Schmehl wrote: > http://www.wnd.com/index.php?fa=PAGE.view&pageId=118953 > > Businesses hold world hostage over carbon credits > Even U.N. climate chief tied to new, 'green' extortion scam > > It was never about the climate. > Not sure about all that, but it is sad that it's hard to know w

[Full-disclosure] Global warming - it's all about the money

2009-12-15 Thread Paul Schmehl
http://www.wnd.com/index.php?fa=PAGE.view&pageId=118953 Businesses hold world hostage over carbon credits Even U.N. climate chief tied to new, 'green' extortion scam It was never about the climate. -- Paul Schmehl, Senior Infosec Analyst As if it wasn't already obvious, my opinions are my own a

[Full-disclosure] [SECURITY] [DSA 1952-1] New asterisk packages fix several vulnerabilities

2009-12-15 Thread Steffen Joeris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1952-1 secur...@debian.org http://www.debian.org/security/ Steffen Joeris December 15, 2009

[Full-disclosure] [SECURITY] [DSA 1952-2] End-of-life announcement for asterisk in oldstable

2009-12-15 Thread Steffen Joeris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1952-2 secur...@debian.org http://www.debian.org/security/ Steffen Joeris December 15, 2009

[Full-disclosure] [SECURITY] [DSA 1951-1] New firefox-sage packages fix insufficient input sanitizing

2009-12-15 Thread Steffen Joeris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1951-1 secur...@debian.org http://www.debian.org/security/ Steffen Joeris December 15, 2009

Re: [Full-disclosure] Google Chrome 3.0.195.33 leaks DNS data queries outsitde of proxy if dns pre-fetching is enabled

2009-12-15 Thread dramacrat
*first at all, send to the list please not to me personally and list in cc.* * * *Ignoring the grammar, that's exactly what you just did. And what I just did, because that's default client behavior on a Reply-To-All. * 2009/12/16 Milan Berger > Hi Vlad, > > first at all, send to the list please n

Re: [Full-disclosure] Google Chrome 3.0.195.33 leaks DNS data queries outsitde of proxy if dns pre-fetching is enabled

2009-12-15 Thread Milan Berger
Hi Vlad, first at all, send to the list please not to me personally and list in cc. > (a) If you have a better way than a Tor proxy to avoid DNS leaks from > programs that don't DNS-proxy themselves, feel free to actually *tell* > us what it is, rather than just babble "they aren't the best way".

Re: [Full-disclosure] Google Chrome 3.0.195.33 leaks DNS data queries outsitde of proxy if dns pre-fetching is enabled

2009-12-15 Thread Valdis . Kletnieks
On Tue, 15 Dec 2009 10:14:31 +0100, Milan Berger said: > > the only way to avoid DNS leaks despite most application configuration > > is a transparent Tor proxy that intercepts all DNS and TCP at the > > network layer and performs a redirect to the Tor Tcp and DNS Ports. > > (see man page.) > > B

[Full-disclosure] Trango Broadband Wireless Rogue SU Authentication Bug

2009-12-15 Thread Blair
-- Trango Broadband Wireless M5830 Series Rogue SU Authentication Bug Date : 15 December, 2009 By: Blair - jedibl...@gmail.com -- Background --

[Full-disclosure] [scip-Advisory 4063] PasswordManager Pro 6.1 Script Injection Vulnerability

2009-12-15 Thread Stefan Friedli
PasswordManager Pro 6.1 Script Injection Vulnerability scip AG Vulnerability ID 4063 (12/15/2009) http://www.scip.ch/?vuldb.4063 I. INTRODUCTION "Password Manager Pro is a secure vault for storing and managing shared sensitive information such as passwords, documents and digital identities of en

Re: [Full-disclosure] Google Chrome 3.0.195.33 leaks DNS data queries outsitde of proxy if dns pre-fetching is enabled

2009-12-15 Thread Milan Berger
> > Google Chrome ... DNS ... sent to the system's configured DNS cache. > that is why #1 at top of big red WARNING box about using Tor properly > says: https://www.torproject.org/download.html.en#Warning > "1. Tor only protects Internet applications that are configured to > send their traffic thro

Re: [Full-disclosure] [gif2png] long filename Buffer Overrun

2009-12-15 Thread Razuel Akaharnath
lol... sadly that was not my intention and I basically had no idea about a bugreport & a patched upstream version in debian as i am not a debian user. peace On Tue, Dec 15, 2009 at 1:29 AM, Jubei Trippataka wrote: > >> On Mon, Dec 14, 2009 at 6:14 AM, Razuel Akaharnath wrote: >> >>> Oh I see, Fu